Symantec.com > Security Response > BAT.Mumu.A.Worm

BAT.Mumu.A.Worm

Risk Level 2: Low

Download Removal Tool | Printer Friendly Page

Discovered: June 2, 2003
Updated: February 13, 2007 12:01:58 PM
Also Known As: BAT/Mumu.worm [McAfee], Bat/Mumu-A [Sophos], BAT.Mumu [CA], Worm.Win32.Muma [KAV], BAT_SPYBOT.A [Trend]
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP


BAT.Mumu.A.Worm is a collection of batch files and utilities, as well as a hacktool named Hacktool.Hacline. It is possible that the names and functions of the files may change. The information discussed in this writeup is based on the samples that Security Response has reviewed.

This worm will spread using administrative shares on Windows NT, 2000, and XP systems. The worm will execute on the Windows 95/98/Me systems; however, it does not harm these systems.

NOTE: The detection of BAT.Mumu.A.Worm was updated in the June 18, 2003 virus definitions to account for some samples that contained minor variations to the originally discovered files.

Protection

  • Initial Rapid Release version June 3, 2003
  • Latest Rapid Release version August 20, 2008 revision 017
  • Initial Daily Certified version June 3, 2003
  • Latest Daily Certified version January 20, 2009 revision 048
  • Initial Weekly Certified release date June 3, 2003

Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: More than 1000
  • Number of Sites: More than 10
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Moderate

Damage

  • Damage Level: Low

Distribution

  • Distribution Level: Medium

Writeup By: Neal Hindocha
Search by name
Example: W32.Beagle.AG@mm
2 year protection
Windows Vista Security